Security Incident Response Engineer
On-siteAtlanta, Georgia, United States or Grand Rapids, Michigan, United States
Job Summary
Investigate and respond to cybersecurity incidents involving endpoints, identities, cloud platforms, email systems, applications, and network infrastructure. Perform incident triage, severity classification, impact analysis, containment, eradication, and recovery activities while executing procedures under the Cyber Incident Response Plan. Analyze alerts from EDR, SIEM, and threat intelligence platforms to validate suspicious activity, conduct root cause analysis, and perform proactive threat hunting. Collect and preserve system, endpoint, and identity evidence for forensic triage and timeline reconstruction. Develop and maintain incident response playbooks, tune detection logic, and assist in SOAR workflow implementation. Track operational metrics including MTTD and MTTR, produce executive summaries, and provide mentorship to analysts. Participate in after-hours on-call rotations and tabletop exercises.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related discipline
- Minimum 3 years of progressive information security experience
- Strong understanding of incident response methodologies, attack lifecycle, and containment strategies
- Experience with one or more EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, or equivalent
- Experience with SIEM technologies such as Microsoft Sentinel, Google SecOps, Splunk, QRadar, or similar platforms
- Knowledge of Microsoft 365, Entra ID, Active Directory, and cloud security concepts
- Understanding of MITRE ATT&CK, threat intelligence, and threat hunting methodologies
- Familiarity with Windows, Linux, and macOS operating systems
- Ability to analyze logs, indicators of compromise (IOCs), and attacker techniques
- Experience with PowerShell, Python, KQL, or other scripting/query languages
- Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.